Forwarded with permission.

So there *is* a BTNS implementation, after all. Albeit
only for OpenBSD -- but this means FreeBSD is next, and
Linux to follow.

> Apropos IPsec, I've tried searching for any BTNS (opportunistic encryption 
> mode for
> IPsec) implementations, and even the authors of the RFC are not aware of any. 
> Obviously, having a working OE BTNS implementation in Linux/*BSD would be a 
> very valuable thing, as an added, transparent protection layer against 
> passive attacks. There are many IPsec old hands here, it is probably just a 
> few man-days
> worth of work. It should be even possible to raise some funding for such a 
> project. Any takers?

Hi. I saw this message in the archive, and have not figured out how to reply to 
that one. But I felt this knowledge needed to be spread. Maybe you can post it 
to the list?

My friend "MC" have in fact implemented BTNS! Check this out:

I think I can speak for him and say that he would love to have that 
implementation be known to the others on the list, and would love others to add 
to his work, so we can get real network security without those spooks spoiling 

"My son has spoken the truth, and he has sacrificed more than either the 
president of the United States or Peter King have ever in their political 
careers or their American lives. So how they choose to characterize him really 
doesn't carry that much weight with me." -- Edward Snowden's Father

